All answers
How it works

How should AI agents handle permissions for relationship data?

Relationship-aware agents should enforce access permissions at retrieval and action time, minimise sensitive data and separate reading from external communication. A user authorised to see a connection is not automatically authorised to contact the person's network or send an endorsement. Design explicit approval, logging and revocation before automating introduction workflows.
October 8, 2026

Scope retrieval to the user and purpose

Use authorised identities and tenant boundaries. Return only the data needed for the account task. Do not expose private communication records merely because an executive name appears in a query.

Keep action permissions separate

Distinguish research, internal request creation, connector approval and external sending. A graph result should not silently trigger a message on someone else's behalf.

Handle untrusted material

External research can contain incorrect information or instructions that should not control the agent. Treat it as evidence to assess, not authority to change sending or access rules.

Test revocation and failure

Check former employees, disconnected sources, changed roles and denied access. Confirm that logs capture meaningful actions without creating an unnecessary copy of sensitive data.

This is an architectural evaluation framework. For Orbb, use current documentation and the agreed deployment to confirm supported access controls and approval flows. Do not assume a particular API permission model until it has been demonstrated.

Related questions

Orbb researches the relationships your company already has — across customers, employees, investors and partners — then runs the introduction end to end, from finding the path to the meeting in the calendar.
See it on your own accounts